Replies: 1 comment
-
|
No, JIT Groups doesn't work with workforce identity. JIT Groups manages Cloud Identity groups. It creates groups, adds/removes memberships as necessary, and can grant groups access to Google Cloud resources. W.r.t. workforce identity, the challenge is:
I understand the use case, but I'm not sure such a model is viable. I'd see three options:
-Johannes |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I'm working on a buildout that has some specific requirements where I'll have project folders for various customers, each needing different levels of access to only their projects. Each customer has their own external domain/directory where users are assigned to groups with different levels of access. My goal was to possibly leverage JIT Groups so that a customer would login through their external IDP into GCP with Workforce Identity, they would then be able to request roles that their account would have access to and perform whatever they need to do.
Is it possible for JIT Groups to work with Workforce Identity so identities from external IDPs and domains can login?
Thank you
Beta Was this translation helpful? Give feedback.
All reactions